Metabase Zero-Day Exploited in the Wild, Exposing Admin Access and Sensitive Data

August 8, 2026 1 Min Read 0

Threat Intelligence Brief

Curated summary with source attribution

Source: securityaffairs.com

Threat Risk: High
Victim: Organizations utilizing self-hosted Metabase BI platforms
Incident: Exploitation of a zero-day SQL injection vulnerability in Metabase.
Impact: Full administrative takeover and potential exfiltration of sensitive data from connected data warehouses.
Attacker: Unidentified threat actors
Analysis: The vulnerability stems from an unauthenticated SQL injection flaw in the password reset endpoint. Successful exploitation enables attackers to escalate privileges to administrator and harvest credentials for connected backend databases. While Cloud users are patched, self-hosted environments remain highly vulnerable if not updated.
Recommendations: Update self-hosted Metabase instances to the latest patched versions (e.g., 0.63.5 or 0.62.9).; Block the /api/session/reset_password endpoint at the network level if immediate patching is not possible.; Audit application logs for POST requests to /api/session/reset_password that resulted in 400 status codes.
Source: Security Affairs

Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source

Leave a Reply

Your email address will not be published. Required fields are marked *